Skip to content

About

Zero knowledge encrypted virtual filesystem — AES-256-GCM + RSA secure sharing + FUSE mount + Flask dashboard. Published at IEEE ICSFT 2026.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

Cryptbox 2.0

A zero-knowledge, client-side encrypted virtual filesystem for cloud storage.

CI Live Demo Published License: MIT Python

Try the live demo → - AES-256-GCM encryption running entirely in your browser, no install required.


Cryptbox 2.0 encrypts your files before they ever touch a sync folder like Dropbox or iCloud. The cloud provider only ever sees ciphertext, encrypted metadata, and RSA-signed integrity proofs - never a plaintext byte, and never your encryption keys. It's a from-scratch re-engineering of the original MIT Cryptobox project, rebuilt around modern authenticated encryption, RSA-based secure sharing, digital signatures, and a real web dashboard.

This repository is the reference implementation behind our paper published at IEEE ICSFT 2026 (see Citation).

Contents

Features

  • AES-256-GCM authenticated encryption for every file - confidentiality and tamper-detection in one primitive.
  • PBKDF2-HMAC-SHA256 key derivation (100,000 iterations, random 16-byte salt per file) - a password never gets used as a key directly.
  • RSA key management for signing and secure sharing, with private keys written to disk at mode 0600.
  • RSA-PSS/SHA-256 digital signatures on every encrypted file, verified automatically on open.
  • Secure multi-user sharing - a file's password is RSA-wrapped per recipient into a portable .json bundle. The plaintext password never crosses the network.
  • Encrypted metadata - original filenames, MIME types, and timestamps are encrypted separately from file contents, so directory listings on the cloud side leak nothing.
  • FUSE-mounted virtual drive - once mounted, encrypted storage behaves like an ordinary folder; files decrypt on open and re-encrypt on save.
  • Web dashboard (Flask) - encrypt, decrypt, share, sign-verify, and manage keys from a browser, no FUSE mount required.
  • CLI (Click) - init, mount, unmount, status, export-key, share, receive.

How it's built

User
 ├── CLI (Click)  ──┐
 └── Web Dashboard ─┼──►  Cryptographic Core
                     │      FileEncryptor (AES-256-GCM)
                     │      RSAKeyManager (RSA-2048)
                     │      DigitalSignature (RSA-PSS/SHA-256)
                     │      SecureSharing / KeyExchange
                     │      MetadataManager (encrypted filenames/attrs)
                     │      ConfigManager (passwords, mount point, prefs)
                     ▼
              CryptboxFS (FUSE layer)
              transparent encrypt-on-write / decrypt-on-open
                     │
                     ▼
        Local encrypted storage (*.enc, *.sig)
                     │
                     ▼
     Cloud sync (Dropbox / iCloud / etc.) - ciphertext only

Full module-by-module breakdown, including the exact data flow for encrypting and sharing a file, is in docs/architecture.md.

Security model

Property Mechanism
File confidentiality AES-256-GCM, 256-bit key, 96-bit nonce, 128-bit tag
Key derivation PBKDF2-HMAC-SHA256, 100,000 iterations, per-file random salt
File integrity AES-GCM auth tag + RSA-PSS/SHA-256 signature over ciphertext
Password sharing RSA-2048-OAEP, wrapped per recipient, zero plaintext transit
Metadata privacy AES-256-GCM over filename/MIME/timestamp JSON
Key-at-rest protection Private key file permissions forced to 0600

Threat model, verified guarantees, and - just as important - the honest list of current limitations (RSA-2048 vs. the paper's RSA-4096, no forward secrecy, TOFU-only key trust) are documented in docs/security_analysis.md.

Quick start

git clone https://github.com/krishnavarma024/cryptbox-2.0.git
cd cryptbox-2.0
python3 -m venv venv && source venv/bin/activate
pip install -r requirements.txt

python gui/dashboard.py
# -> open http://localhost:5000

That's the whole setup for the web dashboard - no FUSE, no system packages. FUSE mounting (cryptbox mount) needs macFUSE (macOS) or libfuse2 (Linux) installed separately; see docs/user_guide.md.

Using it

cryptbox init                                    # generate RSA keys + set password
cryptbox status                                  # check config / mount state
cryptbox export-key alice.json --name Alice --email alice@example.com
cryptbox share secret.txt.enc bob_public_key.json -o secret.bundle.json
cryptbox receive secret.bundle.json secret.txt.enc
cryptbox mount                                   # requires FUSE

A full walkthrough of both the dashboard and the CLI - including a troubleshooting table for the classic "forgot how to run it" moment - is in docs/user_guide.md.

Project structure

cryptbox/            Core package: encryption, keys, signatures, sharing,
                      metadata, config, FUSE filesystem, CLI entry point
gui/                  Flask web dashboard + template
utils/                Crypto primitives (PBKDF2/SHA-256) + file helpers
tests/                35 pytest tests across every module
docs/                 architecture.md, security_analysis.md, user_guide.md
web-demo/             Static, client-side AES-256-GCM demo (GitHub Pages)
demo_presentation.py  Scripted end-to-end walkthrough used for the paper's figures

Testing

pytest -v

35 tests, ~10s: crypto primitives, AES-256-GCM round-trips and tamper detection, RSA key management, digital signatures, encrypted metadata, the FUSE Operations layer (skipped gracefully if libfuse isn't present), and the full multi-user secure-sharing workflow. CI runs the whole suite on Python 3.10-3.12 and additionally boots the Flask dashboard and hits its API end to end - see .github/workflows/ci.yml.

Live demo vs. the full project

The GitHub Pages demo is a pure client-side reimplementation of just the AES-256-GCM file encryption (cryptbox/encryption.py), using the browser's native crypto.subtle - nothing is uploaded anywhere. It uses the exact same container format (salt[16] || nonce[12] || tag[16] || ciphertext), so a file encrypted in the browser decrypts correctly with the real Python FileEncryptor and vice versa - verified with a Node.js/Python interop test during development.

It intentionally doesn't include RSA key management, secure sharing, signatures, or the FUSE mount. For those, clone the repo and run the real thing (see Quick start).

Roadmap

  • Default to RSA-4096 (matching the published paper); keep RSA-2048 as an opt-in for speed.
  • Random per-installation salt for metadata key derivation.
  • Optional Argon2id path for password-based key derivation.
  • Lightweight key-trust UX (fingerprint display, TOFU change warnings) for secure sharing.

Citation

If you reference this work, please cite:

K. Varma, B. Teja, and S. G, "Cryptbox 2.0: A Secure Client-Side Encrypted File Storage and Sharing Framework," presented at the IEEE International Conference on Smart Systems and Future Technologies (ICSFT) 2026.

@inproceedings{varma2026cryptbox,
  title     = {Cryptbox 2.0: A Secure Client-Side Encrypted File Storage and Sharing Framework},
  author    = {Varma, Krishna and Teja, Bharath and G, Sreeraag},
  booktitle = {Proceedings of the IEEE International Conference on Smart Systems and Future Technologies (ICSFT)},
  year      = {2026},
  publisher = {IEEE}
}

License

MIT - see LICENSE.

Author

Krishna Varma - krishnavarma024@gmail.com Department of Computer Science and Engineering, Amrita School of Computing, Bengaluru, Amrita Vishwa Vidyapeetham.

About

Zero knowledge encrypted virtual filesystem — AES-256-GCM + RSA secure sharing + FUSE mount + Flask dashboard. Published at IEEE ICSFT 2026.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages